D-Link DWS-1008 Product Manual - Page 378

web-portal, web-portal-wired, Once the SODA agent files have been downloaded

Page 378 highlights

SODA functionality on a switch is configured as follows: 1. Using SODA Manager, a network administrator creates a SODA agent based on the security needs of the network. 2. The network administrator exports the SODA agent files from SODA Manager, and saves them as a .zip file. 3. The SODA agent .zip file is uploaded to the switch using TFTP. 4. The SODA agent files are installed on the switch using a CLI command that extracts the files from the .zip file and places them into a specified directory. 5. SODA functionality is enabled for an SSID that also has Web Portal WebAAA configured. Once configured, SODA functionality works as follows: 1. A user connects to an AP managed by a service profile where SODA functionality is enabled. 2. Since the Web Portal WebAAA feature is enabled for the SSID, a portal session is started for the user, and the user is placed in the VLAN associated with the web-portal-ssid or web-portal-wired user. 3. The user opens a browser window and is redirected to a login page, where he or she enters a username and password. 4. The user is redirected to a page called index.html, which exists in the SODA agent directory on the switch. 5. The redirection to the index.html page causes the SODA agent files to be downloaded to the user's computer. 6. Once the SODA agent files have been downloaded, one of the following can take place: a. If the switch is configured to enforce the SODA agent security checks (the default), then the SODA agent checks are run on the user's computer. If the user's computer passes the checks, then a customizable success page is loaded in the browser window. The user is then moved from the portal VLAN to his or her configured VLAN and granted access to the network. b. If the switch is configured not to enforce the SODA agent security checks, then the user is moved from the portal VLAN to his or her configured VLAN and granted access to the network, without waiting for the SODA agent checks to be completed. c. If the user's computer fails one of the SODA agent checks, then a customizable failure page is loaded in the browser window. The user is then disconnected from the network, or can optionally be granted limited network access, based on a specified security ACL. D-Link DWS-1008 User Manual 359

  • 1
  • 2
  • 3
  • 4
  • 5
  • 6
  • 7
  • 8
  • 9
  • 10
  • 11
  • 12
  • 13
  • 14
  • 15
  • 16
  • 17
  • 18
  • 19
  • 20
  • 21
  • 22
  • 23
  • 24
  • 25
  • 26
  • 27
  • 28
  • 29
  • 30
  • 31
  • 32
  • 33
  • 34
  • 35
  • 36
  • 37
  • 38
  • 39
  • 40
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • 48
  • 49
  • 50
  • 51
  • 52
  • 53
  • 54
  • 55
  • 56
  • 57
  • 58
  • 59
  • 60
  • 61
  • 62
  • 63
  • 64
  • 65
  • 66
  • 67
  • 68
  • 69
  • 70
  • 71
  • 72
  • 73
  • 74
  • 75
  • 76
  • 77
  • 78
  • 79
  • 80
  • 81
  • 82
  • 83
  • 84
  • 85
  • 86
  • 87
  • 88
  • 89
  • 90
  • 91
  • 92
  • 93
  • 94
  • 95
  • 96
  • 97
  • 98
  • 99
  • 100
  • 101
  • 102
  • 103
  • 104
  • 105
  • 106
  • 107
  • 108
  • 109
  • 110
  • 111
  • 112
  • 113
  • 114
  • 115
  • 116
  • 117
  • 118
  • 119
  • 120
  • 121
  • 122
  • 123
  • 124
  • 125
  • 126
  • 127
  • 128
  • 129
  • 130
  • 131
  • 132
  • 133
  • 134
  • 135
  • 136
  • 137
  • 138
  • 139
  • 140
  • 141
  • 142
  • 143
  • 144
  • 145
  • 146
  • 147
  • 148
  • 149
  • 150
  • 151
  • 152
  • 153
  • 154
  • 155
  • 156
  • 157
  • 158
  • 159
  • 160
  • 161
  • 162
  • 163
  • 164
  • 165
  • 166
  • 167
  • 168
  • 169
  • 170
  • 171
  • 172
  • 173
  • 174
  • 175
  • 176
  • 177
  • 178
  • 179
  • 180
  • 181
  • 182
  • 183
  • 184
  • 185
  • 186
  • 187
  • 188
  • 189
  • 190
  • 191
  • 192
  • 193
  • 194
  • 195
  • 196
  • 197
  • 198
  • 199
  • 200
  • 201
  • 202
  • 203
  • 204
  • 205
  • 206
  • 207
  • 208
  • 209
  • 210
  • 211
  • 212
  • 213
  • 214
  • 215
  • 216
  • 217
  • 218
  • 219
  • 220
  • 221
  • 222
  • 223
  • 224
  • 225
  • 226
  • 227
  • 228
  • 229
  • 230
  • 231
  • 232
  • 233
  • 234
  • 235
  • 236
  • 237
  • 238
  • 239
  • 240
  • 241
  • 242
  • 243
  • 244
  • 245
  • 246
  • 247
  • 248
  • 249
  • 250
  • 251
  • 252
  • 253
  • 254
  • 255
  • 256
  • 257
  • 258
  • 259
  • 260
  • 261
  • 262
  • 263
  • 264
  • 265
  • 266
  • 267
  • 268
  • 269
  • 270
  • 271
  • 272
  • 273
  • 274
  • 275
  • 276
  • 277
  • 278
  • 279
  • 280
  • 281
  • 282
  • 283
  • 284
  • 285
  • 286
  • 287
  • 288
  • 289
  • 290
  • 291
  • 292
  • 293
  • 294
  • 295
  • 296
  • 297
  • 298
  • 299
  • 300
  • 301
  • 302
  • 303
  • 304
  • 305
  • 306
  • 307
  • 308
  • 309
  • 310
  • 311
  • 312
  • 313
  • 314
  • 315
  • 316
  • 317
  • 318
  • 319
  • 320
  • 321
  • 322
  • 323
  • 324
  • 325
  • 326
  • 327
  • 328
  • 329
  • 330
  • 331
  • 332
  • 333
  • 334
  • 335
  • 336
  • 337
  • 338
  • 339
  • 340
  • 341
  • 342
  • 343
  • 344
  • 345
  • 346
  • 347
  • 348
  • 349
  • 350
  • 351
  • 352
  • 353
  • 354
  • 355
  • 356
  • 357
  • 358
  • 359
  • 360
  • 361
  • 362
  • 363
  • 364
  • 365
  • 366
  • 367
  • 368
  • 369
  • 370
  • 371
  • 372
  • 373
  • 374
  • 375
  • 376
  • 377
  • 378
  • 379
  • 380
  • 381
  • 382
  • 383
  • 384
  • 385
  • 386
  • 387
  • 388
  • 389
  • 390
  • 391
  • 392
  • 393
  • 394
  • 395
  • 396
  • 397
  • 398
  • 399
  • 400
  • 401
  • 402
  • 403
  • 404
  • 405
  • 406
  • 407
  • 408
  • 409
  • 410
  • 411
  • 412
  • 413
  • 414
  • 415
  • 416
  • 417
  • 418
  • 419
  • 420
  • 421
  • 422
  • 423
  • 424
  • 425
  • 426
  • 427
  • 428
  • 429
  • 430
  • 431
  • 432
  • 433
  • 434
  • 435
  • 436
  • 437
  • 438
  • 439
  • 440
  • 441
  • 442
  • 443
  • 444
  • 445
  • 446
  • 447
  • 448
  • 449
  • 450
  • 451
  • 452
  • 453
  • 454
  • 455
  • 456
  • 457
  • 458
  • 459
  • 460
  • 461
  • 462
  • 463
  • 464
  • 465
  • 466
  • 467
  • 468
  • 469
  • 470
  • 471
  • 472
  • 473
  • 474
  • 475
  • 476
  • 477
  • 478
  • 479
  • 480
  • 481
  • 482
  • 483
  • 484
  • 485
  • 486
  • 487
  • 488
  • 489
  • 490
  • 491
  • 492
  • 493
  • 494
  • 495
  • 496
  • 497
  • 498
  • 499
  • 500
  • 501
  • 502

D-Link DWS-1008 User Manual
²´·
SODA functionality on a switch is configured as follows:
1. Using SODA Manager, a network administrator creates a SODA agent based on the
security needs of the network.
2. The network administrator exports the SODA agent files from SODA Manager, and saves
them as a .zip file.
3. The SODA agent .zip file is uploaded to the switch using TFTP.
4. The SODA agent files are installed on the switch using a CLI command that extracts the
files from the .zip file and places them into a specified directory.
5. SODA functionality is enabled for an SSID that also has Web Portal WebAAA configured.
Once configured, SODA functionality works as follows:
1. A user connects to an AP managed by a service profile where SODA functionality is
enabled.
2. Since the Web Portal WebAAA feature is enabled for the SSID, a portal session is started
for the user, and the user is placed in the VLAN associated with the
web-portal-
ssid
or
web-portal-wired
user.
3. The user opens a browser window and is redirected to a login page, where he or she
enters a username and password.
4.
The user is redirected to a page called
index.html
, which exists in the SODA agent directory
on the switch.
5. The redirection to the
index.html
page causes the SODA agent files to be downloaded to
the user’s computer.
6. Once the SODA agent files have been downloaded, one of the following can take place:
a.
If the switch is configured to enforce the SODA agent security checks (the default),
then the SODA agent checks are run on the user’s computer. If the user’s computer
passes the checks, then a customizable success page is loaded in the browser
window. The user is then moved from the portal VLAN to his or her configured
VLAN and granted access to the network.
b. If the switch is configured not to enforce the SODA agent security checks, then
the user is moved from the portal VLAN to his or her configured VLAN and
granted access to the network, without waiting for the SODA agent checks to be
completed.
c. If the user’s computer fails one of the SODA agent checks, then a customizable
failure page is loaded in the browser window. The user is then disconnected from
the network, or can optionally be granted limited network access, based on a
specified security ACL.